Unfortunately, security properties address one piece of the overall goal, and are sometimes conflicting. So you have to first identify what _your_ goal is, in terms of security, and implement measures that apply to the properties that are important to that goal.
25.03.2025 19:44
π 0
π 0
π¬ 0
π 0
Us: Use MFA for security
Everyone: OK, secure!
Us: Well, only if youβre not being phished, and no one can subvert the delivery mechanism, and β¦
Everyone: π
25.03.2025 19:44
π 0
π 0
π¬ 1
π 0
We (security people) have done a really bad job communicating what security properties are (and arenβt).
Us: Use Signal for security
Everyone: OK, using Signal, now Iβm **secure**!
Us: Well, only if the ends arenβt compromised, and you can trust the other parties, and β¦
Everyone: π
25.03.2025 19:44
π 0
π 0
π¬ 1
π 0
Security isnβt binary. We need to somehow teach people to think in terms of simple threat models.
25.03.2025 19:44
π 0
π 0
π¬ 1
π 0
+1
12.03.2025 12:30
π 0
π 0
π¬ 0
π 0
So Soft, so ICEy
11.03.2025 18:44
π 1
π 0
π¬ 0
π 0
Iβm getting excited for RE//verse!
18.01.2025 04:07
π 0
π 0
π¬ 0
π 0
We're pleased to announce Natalie Silvanovich @natashenka.bsky.social as the keynote speaker for the inaugural RE//verse. She might have started out hacking Tamagotchis, but she certainly didn't stop there!
18.01.2025 01:19
π 17
π 7
π¬ 1
π 2
Wow, thatβs high praise. Ordering
18.12.2024 03:47
π 0
π 0
π¬ 0
π 0
num
12.12.2024 00:17
π 1
π 0
π¬ 0
π 0
Glad to see youβve gotten on board the Binja train π π
09.12.2024 18:23
π 1
π 0
π¬ 0
π 0
Oh, I never posted my gotofail story on here.
Early 2014, someone came to me about a catastrophic vulnerability in Apple's TLS implementation.
I shit you not, they'd overheard someone at a bar drunkenly bragging about how they were going to sell it to a FVEY intelligence agency for six figures.
17.11.2024 23:22
π 458
π 101
π¬ 7
π 20
A Touch of Pwn - Part I
Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations
Boom! π₯
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: blackwinghq.com/blog/posts/a...
#infosec #security #vulnresearch
21.11.2023 19:49
π 3
π 1
π¬ 0
π 0
A Touch of Pwn - Part I
Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations
Boom! π₯
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: blackwinghq.com/blog/posts/a...
#infosec #security #vulnresearch
21.11.2023 19:49
π 3
π 1
π¬ 0
π 0
There are some legacy security professionals that wear βI donβt codeβ as a badge of honor, but theyβre dying out. Just like traditional system administration was replaced by devops.
05.11.2023 21:55
π 3
π 0
π¬ 0
π 0
how to software, any day.
Although my background is in vulnerability research, this is not only applicable to finding vulns, appsec, etc. Security operations, network security, etc.Β automation is the future (current in mature orgs).
β¦
05.11.2023 21:55
π 1
π 0
π¬ 1
π 0
Advice to juniors or those looking to get into #cybersecurity:
Learn to code
Software is at every level of the stack. Strong software engineering skills will serve you well throughout your career. I would rather teach a strong software engineer security over teaching a traditional security person β¦
05.11.2023 21:53
π 2
π 1
π¬ 1
π 0
π blue sky
05.11.2023 21:48
π 4
π 0
π¬ 0
π 0